Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40792
HistoryJun 05, 2023 - 11:41 a.m.

Integer Overflow

2023-06-0511:41:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
libcap
integer overflow
vulnerability
_libcap_strdup()
application crash

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

libcap is vulnerable to Integer Overflow. The vulnerability occurs in occurs in the_libcap_strdup() function because the string size is not properly validated which allows an attacker to cause an overflow resulting in an application crash.

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%